CVE-2018-4850: Siemens SIMATIC s7-400 Firmware
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below (All versions), SIMATIC S7-400 (incl. F) CPU hardware version 5.0 (All firmware versions < V5.2), SIMATIC S7-400H CPU hardware version 4.5 and below (All versions). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart.
Affected products
- Siemens SIMATIC s7-400 Firmware: up to and including 4.0; before 5.2 (fixed in 5.2)
- Siemens SIMATIC s7-400h Firmware: up to and including 4.5
Published 2018-05-16. Last modified 2026-06-17.